ATT&CKReferencesBleeping Computer - Ryuk WoL

Bleeping Computer - Ryuk WoL

Abrams, L. (2021, January 14). Ryuk Ransomware Uses Wake-on-Lan To Encrypt Offline Devices. Retrieved February 11, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareRyuk

Ryuk has called GetIpNetTable in attempt to identify all mounted drives and hosts that have Address Resolution Protocol (ARP) entries.

T1021.002
SMB/Windows Admin Shares
MalwareRyuk

Ryuk has used the C$ network share for lateral movement.

T1205
Traffic Signaling
MalwareRyuk

Ryuk has used Wake-on-Lan to power on turned off systems for lateral movement.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.